Vice President, Chief Information Security Officer (CISO)

Driven Brands

$199K — $355K *
US-AnywhereRemote in North Carolina, US
Information Technology
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • 15+ years of progressive technology leadership experience in IT infrastructure, cybersecurity, and risk management.
  • Demonstrated experience presenting to Boards and senior stakeholders on cybersecurity and technology risk.
  • Direct experience with internal and external audit processes, including SOX compliance and control remediation.
  • Strong background in managing IT infrastructure across various domains: networks, cloud, and telecommunication services.
  • Professional security or technology management certifications such as CISSP, CISM, or ITIL are preferred.

Responsibilities

  • Lead the enterprise infrastructure strategy and operating model for various technology services.
  • Ensure high standards of service delivery and operational resilience across all company environments.
  • Develop and manage infrastructure roadmaps focused on modernization, cost optimization, and technical debt reduction.
  • Drive operational excellence in incident and change management to improve user experience.
  • Implement and oversee the enterprise cybersecurity strategy and response programs.

Benefits

  • Health and wellness benefits including paid time off and holiday pay.
  • Access to myFlexPay program for early wage access.
  • Variety of technology management certifications supported for employee growth.
Full Job Description
JOB DESCRIPTION:

The Vice President, Chief Information Security Officer is responsible for leading the company's enterprise cybersecurity strategy, governance, risk management, and security operations program.

The CISO serves as the senior cybersecurity advisor to executive leadership, the Board of Directors, and the Audit Committee. This role translates cybersecurity risks into clear business, financial, regulatory, and operational terms and recommends appropriate investments, remediation priorities, and risk-treatment decisions.

The CISO partners with Information Technology, Internal Audit, Legal, Privacy, Finance, Human Resources, Enterprise Risk Management, and business leadership to protect the company's information assets, customers, employees, franchisees, and brand.

How you will Own It:

Cybersecurity Strategy and Governance
  • Develop and execute a multi-year enterprise cybersecurity strategy aligned with business objectives, regulatory requirements, and risk appetite.
  • Establish cybersecurity policies, standards, controls, and governance based on recognized frameworks such as NIST, CIS Controls, and ISO 27001.
  • Define accountability for cybersecurity across corporate functions, brands, technology teams, franchise environments, and third-party providers.
  • Evaluate emerging threats, technologies, regulations, and business risks.
Executive and Board Reporting
  • Serve as the principal cybersecurity advisor to executive leadership, the Board, and the Audit Committee.
  • Establish and maintain a standardized cybersecurity scorecard that tracks progress against defined goals, key risk indicators, control maturity, strategic initiatives, and remediation commitments quarter over quarter.
  • Present scorecard results to executive leadership and the Board, highlighting progress, emerging risks, performance gaps, overdue actions, and matters requiring executive or Board attention.
  • Report on cybersecurity posture, material risks, incidents, control maturity, strategic initiatives, and remediation progress.
  • Advise leadership regarding cybersecurity investments, risk acceptance, and significant control exceptions.
Cyber Risk and Compliance
  • Lead the identification, assessment, prioritization, treatment, and monitoring of enterprise cybersecurity risks.
  • Maintain the cybersecurity risk register and integrate material cyber risks into the enterprise risk management process.
  • Oversee security-related compliance obligations, including SOX, PCI DSS, privacy requirements, and contractual commitments.
  • Partner with Internal Audit, external auditors, Finance, and Legal to support audit readiness and timely remediation of findings.
  • Provide independent challenge regarding control deficiencies, exceptions, compensating controls, and accepted risks.
Security Operations and Incident Response
  • Provide executive oversight of security monitoring, detection, threat intelligence, investigation, containment, and response.
  • Oversee security technologies and services, including SIEM, SOAR, EDR/XDR, email security, cloud security, data protection, and managed security providers.
  • Lead the response to significant cybersecurity incidents and coordinate with Technology, Legal, Privacy, Communications, Finance, Human Resources, insurers, forensic firms, and law enforcement.
  • Maintain and test cybersecurity incident-response plans, escalation procedures, executive communications, and crisis-management processes.
  • Drive corrective actions through post-incident reviews and root-cause analysis.
Identity, Vulnerability and Data Protection
  • Establish security governance for identity lifecycle management, multifactor authentication, privileged access, access reviews, segregation of duties, and non-human identities.
  • Oversee the enterprise vulnerability and exposure management program.
  • Define risk-based remediation, exception, escalation, and reporting requirements.
  • Establish security controls for confidential, personal, financial, employee, customer, and franchisee information.
  • Partner with Legal and Privacy leaders on data-protection and privacy obligations.
Security Architecture, AI Governance and Business Enablement
  • Establish enterprise security architecture principles and secure-design standards.
  • Provide cybersecurity oversight for cloud adoption, applications, digital products, major technology changes, artificial intelligence, and emerging technologies.
  • Partner with Technology, Legal, Privacy, Risk, and business leadership to establish governance for the secure and responsible use of artificial intelligence.
  • Define cybersecurity and data-protection requirements for the evaluation, acquisition, development, deployment, and use of artificial intelligence technologies.
  • Assess and monitor AI-related risks, including sensitive-data exposure, unauthorized use, third-party model risk, access control, regulatory compliance, and model manipulation.
  • Ensure AI initiatives are subject to appropriate security assessment, approval, monitoring, and periodic review.
  • Ensure security requirements are incorporated into architecture, procurement, development, implementation, and change processes.
  • Partner with infrastructure, application, cloud, data, and architecture teams without assuming responsibility for their day-to-day operations.
Third-Party Risk and Transactions
  • Lead the third-party cybersecurity risk management program, including due diligence, assessments, contracting requirements, monitoring, and reassessment.
  • Evaluate risks associated with critical vendors, cloud providers, payment environments, franchise platforms, and outsourced services.
  • Lead cybersecurity due diligence and risk planning for mergers, acquisitions, integrations, divestitures, and transition-service arrangements.
  • Ensure material third-party and transaction-related risks are communicated to executive leadership.
Resilience, Awareness and Leadership
  • Establish cyber-resilience requirements and ensure cyberattack scenarios are included in business continuity and disaster-recovery planning.
  • Maintain oversight of ransomware readiness, backup protection, recovery access, and cyber-recovery testing without owning infrastructure recovery operations.
  • Lead enterprise cybersecurity awareness, phishing simulation, and role-based training programs.
  • Build and develop a high-performing cybersecurity organization.
  • Manage the cybersecurity budget, vendors, managed security providers, and strategic partners.


What you'll Bring:
  • Bachelor's degree in cybersecurity, information systems, computer science, engineering, business, risk management, or a related field; advanced degree preferred.
  • Fifteen or more years of progressive cybersecurity, technology-risk, or related experience.
  • Significant experience leading an enterprise cybersecurity program in a complex, distributed, regulated, or publicly traded organization.
  • Demonstrated experience advising executive leadership, Boards, and Audit Committees.
  • Strong knowledge of cybersecurity frameworks, security operations, incident response, identity and access management, vulnerability management, cloud security, data protection, third-party risk, AI security governance, and regulatory compliance.
  • Experience supporting SOX IT general controls, audits, remediation programs, and business transactions.
  • Experience managing cybersecurity teams, budgets, vendors, and managed security providers.
  • Experience in retail, automotive services, franchise, hospitality, restaurant, or other multi-location consumer-facing industries preferred.
  • Experience supporting organizations with multiple brands, decentralized operations, and complex third-party partner ecosystems preferred.
  • CISSP or CISM certification required or strongly preferred. CRISC, CISA, CCSP, GIAC, or equivalent credentials are beneficial.


Measures of Success
  • Measurable reduction in material cybersecurity risk.
  • Consistent quarter-over-quarter reporting demonstrating progress against defined cybersecurity goals, risk-reduction priorities, control improvements, and remediation commitments.
  • Improved cybersecurity-program maturity and control effectiveness.
  • Timely remediation of vulnerabilities, audit findings, and security deficiencies.
  • Effective detection, containment, communication, and recovery during cybersecurity incidents.
  • Clear and actionable cybersecurity reporting to executive leadership and the Board.
  • Effective governance and security controls for enterprise artificial intelligence adoption.
  • Effective oversight of identity, third-party, data-protection, and regulatory risks.
  • Cybersecurity investments aligned with business priorities and risk reduction.


#LI-DM1

#LI-Remote

#DBCORP

Position Location:
North Carolina

Compensation Range:
$199,200.00 - $355,800.00

Compensation Frequency:
Annual

Base pay offered may vary depending on actual location, job-related knowledge, skills, and experience. Supplemental pay types may include commissions or bonus incentives, depending on the role. Driven Brands offers a variety of health and wellness benefits including paid time off and holiday pay. Details regarding our benefits can be found here: https://www.drivenbrandsbenefits.com

Get early access to 50% of your earned wages at any time through our myFlexPay program.

Similar Jobs

More Jobs at Driven Brands

More Information Technology Jobs

Find similar Vice President, Chief Information Security Officer (CISO) jobs: